← zurück / back

PlantKeeper: Datenschutzerklärung

Stand: 4. September 2026 · English version below

Kurzfassung: so wenig wie möglich, kein Werbe-Tracking, keine Weitergabe zu Werbezwecken, kein Verkauf von Daten. Was trotzdem anfällt, steht hier vollständig. Diese Erklärung gilt für plantkeeper.de, app.plantkeeper.de, api.plantkeeper.de und die App PlantKeeper für Android und iOS.

Verantwortlicher

Alexander West · [email protected]
Anschrift siehe Impressum.

Ein Datenschutzbeauftragter ist nicht bestellt; die gesetzlichen Voraussetzungen dafür liegen nicht vor.

Warteliste

Nutzerkonto in der App

Gerätedaten

Messreihen

Standort und Bluetooth in der App

Warum Bluetooth? Ein neues PlantKeeper-Gerät wird per Bluetooth eingerichtet: die App sucht das Gerät in Funkreichweite und überträgt WLAN-Zugangsdaten, Einstellungen und, auf deinen Tipp hin, den Standort. Die WLAN-Zugangsdaten gehen dabei direkt vom Telefon an das Gerät, nicht über den Server. Auf Android ist die Bluetooth-Suche ausdrücklich als "leitet keinen Standort ab" gekennzeichnet (neverForLocation); auf Android 11 und älter verlangt das System für eine Bluetooth-Suche technisch trotzdem die Standortberechtigung, die App wertet den Standort dabei nicht aus.

Warum Standort? Ausschließlich, damit dein Gerät die Wettervorhersage am richtigen Ort abruft. Die App fragt einmalig und nur nach einem ausdrücklichen Tippen auf den Knopf, holt eine grobe Ortung und schreibt sie per Bluetooth an das Gerät. Es gibt keine Ortung im Hintergrund, keine wiederholte Abfrage und keine Bewegungsprofile. Wer den Standort nicht geben möchte, tippt stattdessen den Ortsnamen ein.

Der Rückweg: beim nächsten Kontakt des Geräts mit dem Server sind die Koordinaten Teil des Gerätezustands (siehe Gerätedaten) und liegen dann auch auf dem Server. Rechtsgrundlage für die Ortung im Telefon ist deine Einwilligung über den Systemdialog (Art. 6 Abs. 1 lit. a DSGVO), für die Nutzung im Gerät und in der App Art. 6 Abs. 1 lit. b DSGVO.

Um zu deinen Koordinaten einen Ortsnamen anzuzeigen, nutzt die App den im Betriebssystem eingebauten Geocoder. Ein eigener Netzdienst wird dabei nicht angesprochen.

Wetterdaten

Das Gerät fragt die Vorhersage selbst ab, direkt aus deinem WLAN. An api.open-meteo.com gehen dabei die Koordinaten deines Beets und die IP-Adresse deines Internetanschlusses. Trägst du einen Ortsnamen statt Koordinaten ein, geht dieser Ortsname an geocoding-api.open-meteo.com, um daraus Koordinaten zu machen. Ein Konto oder eine Kennung wird nicht mitgeschickt.

Der Server fragt zusätzlich für die Anzeige in der App ab, aber nicht je Gerät: gecacht wird je Gitterzelle von 0,1 Grad (etwa 11 km, gerundet). Dabei gehen nur diese gerundeten Koordinaten und die IP-Adresse des Servers hinaus, keine Geräte- oder Kontokennung.

Trägst du einen Ortsnamen ein, schickt auch der Server diesen Namen an geocoding-api.open-meteo.com, um daraus Koordinaten zu machen, und merkt sich das Ergebnis (Ortsname, Koordinaten, Zeitpunkt) in einem Cache. Ein Eintrag, den 30 Tage niemand mehr gebraucht hat, wird gelöscht. Auch dabei geht keine Geräte- oder Kontokennung hinaus.

Betreiber ist Open-Meteo mit Sitz in der Schweiz (Datenschutzhinweise). Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO, ohne diese Abfrage kann das Gerät nicht bedarfsgerecht gießen.

Push-Benachrichtigungen

Diagnosedaten in der App

Reichweitenmessung (Plausible)

Die Startseite nutzt eine selbst betriebene Instanz von Plausible Analytics, um zu zählen, wie viele Menschen die Seite besuchen und ob sich jemand in die Warteliste einträgt (Art. 6 Abs. 1 lit. f DSGVO: berechtigtes Interesse an anonymer Reichweitenmessung). Plausible setzt keine Cookies, speichert keine IP-Adressen und bildet keine personenbezogenen Profile; die Daten liegen auf demselben selbst betriebenen Server. Beim Wartelisten-Eintrag wird nur die gewählte Preisspanne und die Sprache gezählt, nie die E-Mail-Adresse.

Server-Logs und Cloudflare

Der Server verarbeitet die IP-Adresse des Aufrufs technisch bedingt zur Auslieferung und für Rate-Limits (Missbrauchsschutz, Art. 6 Abs. 1 lit. f DSGVO). Sie wird nur flüchtig im Arbeitsspeicher für die Zählung der letzten 60 Sekunden gehalten und nicht mit dem Konto oder der Warteliste verknüpft. Ein Zugriffs-Log führt der Server nicht: das Access-Log der Anwendung ist abgeschaltet, damit keine IP-Adressen in Log-Dateien landen. Gezählt wird nur, wie viele Aufrufe je Tag auf welche Gruppe von Adressen fielen, ohne IP und ohne Kontobezug.

Der Server steht selbst betrieben in Deutschland, erreichbar über Cloudflare. Cloudflare terminiert dabei die TLS-Verbindung und verarbeitet damit sämtliche Anfragedaten einschließlich IP-Adressen. Cloudflare ist insoweit Auftragsverarbeiter; Grundlage ist der Auftragsverarbeitungsvertrag (Cloudflare DPA) nach Art. 28 DSGVO, für die USA gestützt auf EU-Standardvertragsklauseln und das EU-US Data Privacy Framework.

Speicherdauer

Was nicht stattfindet

Keine Weitergabe zu Werbezwecken, kein Verkauf von Daten, kein Profiling, keine automatisierte Entscheidung im Einzelfall nach Art. 22 DSGVO, keine Werbe-Cookies, keine Werbenetzwerke. Außer den hier genannten Empfängern werden keine Daten an Dritte weitergegeben.

Deine Rechte

Du hast das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen auf Grundlage berechtigter Interessen (Art. 21 DSGVO). Erteilte Einwilligungen kannst du jederzeit mit Wirkung für die Zukunft widerrufen (Art. 7 Abs. 3 DSGVO); die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung bleibt unberührt. Eine formlose Mail an [email protected] genügt.

Außerdem kannst du dich bei einer Aufsichtsbehörde beschweren (Art. 77 DSGVO). Zuständig ist das Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, oder die Behörde deines gewöhnlichen Aufenthaltsorts.

Konto löschen

Du löschst dein Konto selbst in der App: Konto-Menü, "Konto löschen", Bestätigung mit deinem Passwort. Danach passiert Folgendes: das Konto samt E-Mail-Adresse, Passwort-Hash und Push-Token ist weg. Deine Geräte werden herrenlos und behalten keine Daten: Verlauf, Meldungen, Gieß-Historie, Zustand und Name werden sofort gelöscht. Für jedes Gerät wird ein Werksreset eingereiht, den es beim nächsten Kontakt abholt; danach ist auch die Gerätezeile weg. Meldet sich ein Gerät nie mehr, wird die Zeile nach 90 Tagen ohne Kontakt gelöscht.


PlantKeeper: Privacy Policy

Last updated: 4 September 2026 · The German version above is the legally binding one.

Short version: as little as possible, no advertising trackers, no sharing for advertising, no selling of data. Everything that does come up is listed here. This policy covers plantkeeper.de, app.plantkeeper.de, api.plantkeeper.de and the PlantKeeper app for Android and iOS.

Who is responsible

Alexander West · [email protected]
Postal address in the legal notice.

No data protection officer has been appointed; the legal conditions requiring one are not met.

Waitlist

User account in the app

Device data

Measurement series

Location and Bluetooth in the app

Why Bluetooth? A new PlantKeeper device is set up over Bluetooth: the app looks for the device in radio range and transfers Wi-Fi credentials, settings and, when you tap for it, the location. Wi-Fi credentials go straight from the phone to the device, not through the server. On Android the Bluetooth scan is explicitly flagged as "derives no location" (neverForLocation); on Android 11 and older the system still technically requires the location permission for a Bluetooth scan, and the app does not evaluate location there.

Why location? Only so your device fetches the weather forecast for the right place. The app asks once and only after you explicitly tap the button, takes a coarse fix and writes it to the device over Bluetooth. There is no background location, no repeated polling and no movement profiles. If you would rather not share a location, type the place name instead.

The way back: the next time the device contacts the server, the coordinates are part of the device state (see device data) and are then stored on the server too. The legal basis for the fix on the phone is your consent via the system dialog (Art. 6(1)(a) GDPR), for its use in the device and the app Art. 6(1)(b) GDPR.

To show a place name for your coordinates the app uses the geocoder built into the operating system. No separate network service is contacted.

Weather data

The device fetches the forecast itself, straight from your Wi-Fi. The coordinates of your plants and the IP address of your internet connection go to api.open-meteo.com. If you enter a place name instead of coordinates, that name goes to geocoding-api.open-meteo.com to be turned into coordinates. No account and no identifier is sent along.

The server additionally fetches the forecast for the display in the app, but not per device: it caches per grid cell of 0.1 degrees (about 11 km, rounded). Only those rounded coordinates and the server's IP address leave the server, no device or account identifier.

If you enter a place name, the server also sends that name to geocoding-api.open-meteo.com to turn it into coordinates and keeps the result (place name, coordinates, time) in a cache. An entry nobody has needed for 30 days is deleted. No device or account identifier is sent here either.

The operator is Open-Meteo, based in Switzerland (privacy information). Legal basis: Art. 6(1)(b) GDPR, without this request the device cannot water according to need.

Push notifications

Diagnostic data in the app

Analytics (Plausible)

The landing page uses a self-hosted Plausible Analytics instance to count how many people visit the page and whether someone signs up for the waitlist (Art. 6(1)(f) GDPR: legitimate interest in anonymous reach measurement). Plausible sets no cookies, stores no IP addresses and builds no personal profiles; the data stays on the same self-hosted server. On waitlist sign-up only the chosen price band and the language are counted, never the email address.

Server logs and Cloudflare

The server processes the IP address of a request for delivery and for rate limiting (abuse protection, Art. 6(1)(f) GDPR). It is held only briefly in memory to count the last 60 seconds and is not linked to your account or the waitlist. The server keeps no access log: the application's access log is switched off so that no IP addresses end up in log files. All that is counted is how many requests per day hit which group of endpoints, without IP and without any link to an account.

The server is self-hosted in Germany and reachable through Cloudflare. Cloudflare terminates the TLS connection and thereby processes all request data including IP addresses. Cloudflare acts as a processor in that respect; the basis is the Cloudflare data processing addendum under Art. 28 GDPR, for the USA backed by EU standard contractual clauses and the EU-US Data Privacy Framework.

Retention

What does not happen

No sharing for advertising, no selling of data, no profiling, no automated individual decision-making under Art. 22 GDPR, no advertising cookies, no ad networks. Apart from the recipients named here, no data is passed to third parties.

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing up to that point is unaffected. A plain email to [email protected] is enough.

You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent one is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 27, 91522 Ansbach, or the authority where you usually live.

Deleting your account

You delete your account yourself in the app: account menu, "Konto löschen", confirmed with your password. What happens then: the account with your email address, password hash and push token is gone. Your devices become unowned and keep no data: history, notices, watering history, state and name are deleted immediately. A factory reset is queued for each device and picked up on its next contact; after that the device row is gone too. If a device never reports again, its row is deleted after 90 days without contact.